2024 CVE Vulnerabilities

39,217 CVEs published in 2024.

CVE IDSeverityCVSSDescription
CVE-2024-53684HIGH8.8A cross-site request forgery (csrf) vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1...
CVE-2024-49572MEDIUM6.5A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A special...
CVE-2024-48894HIGH7.5A cleartext transmission vulnerability exists in the WEBVIEW-M functionality of Socomec DIRIS Digiware M-70 1.6.9. A spe...
CVE-2024-48882HIGH7.5A denial of service vulnerability exists in the Modbus TCP functionality of Socomec DIRIS Digiware M-70 1.6.9. A special...
CVE-2024-45370HIGH7.3An authentication bypass vulnerability exists in the User profile management functionality of Socomec Easy Config System...
CVE-2024-39148HIGH8.1The service wmp-agent of KerOS prior 5.12 does not properly validate so-called ‘magic URLs’ allowing an unauthenticated ...
CVE-2024-32388MEDIUM5.3Due to a firewall misconfiguration, Kerlink devices running KerOS prior to 5.12 incorrectly accept specially crafted UDP...
CVE-2024-32384HIGH7.4Kerlink gateways running KerOS prior to version 5.10 expose their web interface exclusively over HTTP, without HTTPS sup...
CVE-2024-56089HIGH7.5An issue in Technitium through v13.2.2 enables attackers to conduct a DNS cache poisoning attack and inject fake respons...
CVE-2024-5540MEDIUM6.9The reflective cross-site scripting vulnerability found in ALC WebCTRL and Carrier i-Vu in versions older than 8.0 affec...
CVE-2024-5539CRITICAL9.2The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows...
CVE-2024-47856CRITICAL9.8In RSA Authentication Agent before 7.4.7, service paths and shortcut paths may be vulnerable to path interception if the...
CVE-2024-14007HIGH8.7Shenzhen TVT Digital Technology Co., Ltd. NVMS-9000 firmware (used by many white-labeled DVR/NVR/IPC products) versions ...
CVE-2024-14015HIGH7.1The WordPress eCommerce Plugin WordPress plugin through 2.9.0 does not sanitise and escape a parameter before outputtin...
CVE-2024-21923HIGH7.3Incorrect default permissions in AMD StoreMI™ could allow an attacker to achieve privilege escalation potentially result...
CVE-2024-21922HIGH7.3A DLL hijacking vulnerability in AMD StoreMI™ could allow an attacker to achieve privilege escalation, potentially resul...
CVE-2024-31405Rejected reason: Voluntarily withdrawn
CVE-2024-8528MEDIUM5.4Reflected XSS using a specific URL in Automated Logic WebCTRL and Carrier i-VU can allow delivery of malicious payload d...
CVE-2024-8527HIGH8.6Open Redirect in URL parameter in Automated Logic WebCTRL and Carrier i-Vu versions 6.0, 6.5, 7.0, 8.0, 8.5, 9.0 may all...
CVE-2024-44664MEDIUM6.5PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the name, summary, review, quality, price, and ...
CVE-2024-44661MEDIUM5.4PHPGurukul Online Shopping Portal 2.0 is vulnerable to Cross Site Scripting (XSS) via the quantity parameter in my-cart....
CVE-2024-44659CRITICAL9.8PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the email parameter in forgot-password.php.
CVE-2024-46335MEDIUM4.6PHPGurukul Complaint Management System 2.0 is vulnerble to Cross Site Scripting (XSS) via the fromdate and todate parame...
CVE-2024-44663MEDIUM6.5PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the product parameter in search-result.php.
CVE-2024-44662MEDIUM6.5PHPGurukul Online Shopping Portal 2.0 is vulnerable to SQL Injection via the username parameter in the admin page.

Check if your code is affected by 2024 CVEs

Strix scans your code and infrastructure for known vulnerabilities automatically.

Scan your code now